AI regulation in Romania is governed primarily by the EU AI Act, the world';s first comprehensive legal framework for artificial intelligence, which applies directly across all EU member states, including Romania. Romanian businesses, developers, and deployers of AI systems must now navigate binding obligations that vary by risk category, with the heaviest requirements falling on high-risk applications in sectors such as healthcare, employment, and critical infrastructure. This guide covers the current regulatory landscape, the national enforcement structure, key compliance obligations, recent developments, and the practical steps that businesses operating in Romania need to take.
The EU AI Act is a directly applicable EU regulation, meaning it does not require separate transposition into Romanian national law. It entered into force across the EU and has been rolling out its obligations in phases, with the most significant provisions now in effect or approaching their compliance deadlines. For businesses operating in Romania, this means the Act';s requirements apply regardless of whether the Romanian legislature has enacted supplementary domestic legislation.
The Act classifies AI systems into four risk tiers: unacceptable risk, high risk, limited risk, and minimal risk. Systems in the unacceptable-risk category - such as social scoring by public authorities or real-time remote biometric identification in public spaces for law enforcement - are prohibited outright. High-risk systems, which include AI used in recruitment, credit scoring, medical devices, and border control, face the most demanding compliance requirements. Limited-risk systems, such as chatbots, carry transparency obligations. Minimal-risk systems, such as spam filters, are largely unregulated.
Romania, as an EU member state, is required to designate a national competent authority responsible for supervising and enforcing the AI Act at the domestic level. The Romanian government has been in the process of formally designating this authority, with the National Authority for Management and Regulation in Communications (ANCOM) and the Romanian Data Protection Authority (ANSPDCP) both playing roles in the broader digital and data governance landscape. Businesses should monitor official announcements from these bodies for enforcement guidance specific to Romania.
A non-obvious requirement for many foreign businesses is that the AI Act applies to providers and deployers established outside the EU if their AI systems are placed on the EU market or their outputs are used within the EU. A company headquartered outside Romania that deploys an AI tool used by Romanian employees or customers is therefore within scope.
Romania is in the process of building its national AI governance infrastructure in line with EU requirements. The AI Act requires each member state to designate at least one national competent authority (NCA) to act as market surveillance authority and notifying authority. Romania';s designation process has been advancing, and businesses should expect formal announcements confirming the lead NCA and any sector-specific supervisory bodies.
In practice, enforcement in Romania will likely be distributed across several bodies depending on the sector in which an AI system operates. The ANSPDCP, Romania';s data protection supervisory authority, is already active in overseeing AI-related data processing under the General Data Protection Regulation (GDPR). Given that many high-risk AI systems process personal data, ANSPDCP is a natural enforcement partner. Sector regulators - such as those overseeing financial services, healthcare, and telecommunications - are expected to play a supervisory role for AI systems deployed within their domains.
The AI Act also establishes a European AI Office within the European Commission, which has direct supervisory powers over general-purpose AI (GPAI) models, including large language models. Providers of GPAI models that are accessible in Romania fall under this centralised EU-level oversight, not solely Romanian national enforcement. This dual-layer structure - EU-level for GPAI, national-level for other AI systems - is a key feature of the framework that businesses must understand.
A common mistake among Romanian businesses is assuming that because national enforcement infrastructure is still being finalised, compliance obligations are not yet active. The AI Act';s prohibited practices provisions have been applicable since the first phase of rollout, and high-risk system requirements are now binding or imminently so. Waiting for full national enforcement machinery to be in place before beginning compliance work is a significant risk.
Compliance obligations under the AI Act differ substantially depending on whether a business is a provider (a company that develops or places an AI system on the market) or a deployer (a company that uses an AI system in a professional context). Both roles carry distinct duties, and a single Romanian business can be both simultaneously.
Providers of high-risk AI systems must meet a demanding set of requirements before placing their system on the market or putting it into service. These include establishing a risk management system, ensuring data governance and data quality for training datasets, producing technical documentation, enabling logging and record-keeping, providing instructions for use, implementing human oversight measures, and achieving accuracy, robustness, and cybersecurity standards. High-risk systems must also undergo a conformity assessment - either self-assessment or third-party assessment depending on the category - and must be registered in the EU database for high-risk AI systems before deployment.
Deployers of high-risk AI systems in Romania carry their own obligations. They must use AI systems in accordance with the provider';s instructions, ensure human oversight, monitor operation, and report serious incidents or malfunctions to the relevant national authority. Deployers who are public bodies face additional transparency requirements, including the obligation to conduct a fundamental rights impact assessment before deploying certain high-risk AI systems.
For AI systems with limited-risk characteristics - most notably chatbots and AI-generated content - the primary obligation is transparency. Users must be informed that they are interacting with an AI system, and AI-generated content that could be mistaken for authentic material must be labelled. This obligation is already active and applies to Romanian businesses deploying customer-facing AI tools.
In practice, founders and compliance officers should consider that the documentation and governance requirements for high-risk systems are substantial. Many underestimate the time needed to produce compliant technical documentation and to implement functioning logging systems. Starting this work early, before a system is deployed, is strongly advisable.
If you are uncertain whether your AI system qualifies as high-risk or how to structure your compliance programme for the Romanian market, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
General-purpose AI (GPAI) models - AI systems trained on broad data that can perform a wide range of tasks - are subject to a distinct set of obligations under the AI Act. This category covers large language models and multimodal foundation models that are made available to other businesses or developers for integration into their own products.
Providers of GPAI models must prepare and maintain technical documentation, provide information and documentation to downstream providers who integrate the model into their own AI systems, comply with EU copyright law (including obligations related to training data transparency), and publish a sufficiently detailed summary of the content used for training. These obligations apply to any provider making a GPAI model available in the EU, including in Romania.
GPAI models that are assessed as posing systemic risk - generally those trained with very large computational resources - face additional obligations. These include conducting model evaluations, assessing and mitigating systemic risks, reporting serious incidents to the European AI Office, and ensuring adequate cybersecurity protections. The European AI Office is the primary regulator for these models, and it has published codes of practice to guide compliance.
For Romanian businesses that integrate third-party GPAI models into their own products or services, the key practical point is that downstream obligations still apply. Using a GPAI model as a component of a high-risk AI system does not transfer all compliance responsibility to the GPAI provider. The downstream provider remains responsible for ensuring the integrated system meets high-risk requirements.
A practical scenario: a Romanian fintech company that builds a credit-scoring tool using a third-party large language model as a component must still conduct a conformity assessment, maintain technical documentation, and register the system in the EU database. The fintech cannot rely solely on the GPAI provider';s compliance documentation to discharge its own obligations.
Several sectors in Romania face heightened AI regulatory scrutiny because they involve high-risk AI applications as defined by the AI Act. Understanding sector-specific dynamics is essential for businesses in these industries.
In healthcare, AI systems used for diagnosis, prognosis, or treatment decisions are classified as high-risk medical devices or standalone high-risk AI systems, depending on their function. Romanian healthcare providers and medtech companies must comply with both the AI Act and the EU Medical Device Regulation (MDR) where applicable. The interaction between these two frameworks requires careful legal analysis, as conformity assessment procedures may overlap or interact.
In financial services, AI systems used for creditworthiness assessment, insurance risk scoring, and fraud detection are high-risk under the AI Act. Romanian banks, insurers, and fintech companies must ensure these systems meet the full suite of high-risk requirements. The National Bank of Romania (BNR) and the Financial Supervisory Authority (ASF) are likely to issue sector-specific guidance on AI governance as the regulatory framework matures.
In employment, AI systems used for recruitment, candidate screening, performance monitoring, and promotion decisions are high-risk. Romanian employers using automated hiring tools or workforce analytics platforms must ensure these systems comply with the AI Act';s high-risk requirements, including human oversight and transparency obligations toward affected workers.
A second practical scenario: a Romanian logistics company that uses an AI system to monitor driver behaviour and make decisions about route assignments or performance reviews is deploying a high-risk AI system in the employment context. The company must implement human oversight mechanisms, maintain logs, and provide workers with meaningful information about how the system affects decisions that concern them.
The GDPR continues to apply alongside the AI Act for any AI system that processes personal data. Romanian businesses must ensure that their AI compliance programmes address both frameworks simultaneously, as the obligations interact in areas such as data minimisation, purpose limitation, and data subject rights.
The AI regulatory landscape in Romania has been evolving rapidly as EU-level obligations have come into force and national implementation work has progressed. Several developments are particularly relevant for businesses planning their compliance strategies.
The prohibition on unacceptable-risk AI practices became applicable in the first phase of the AI Act';s rollout. This means that any Romanian business or public authority using AI systems that fall into the prohibited categories - such as subliminal manipulation techniques, exploitation of vulnerabilities of specific groups, or real-time remote biometric identification in public spaces for law enforcement outside narrow exceptions - must have ceased those practices.
Obligations for GPAI model providers and the governance framework for the European AI Office are now operational. Providers of GPAI models accessible in Romania are subject to these requirements, and the European AI Office has been actively developing codes of practice with industry participation.
The full set of high-risk AI system obligations is now binding or approaching its final compliance deadline. Romanian businesses that have not yet begun their conformity assessment and documentation work are running out of time to complete these processes before enforcement becomes active.
Romania is also expected to designate its national competent authority formally and to establish the market surveillance and enforcement infrastructure required by the AI Act. Businesses should anticipate that once this infrastructure is in place, enforcement activity will increase. Proactive compliance is significantly less costly than responding to regulatory investigations or penalties.
Many underestimate the cross-border complexity of AI compliance. A Romanian subsidiary of a multinational group may need to coordinate its AI compliance programme with parent-company obligations in other jurisdictions, particularly where AI systems are developed centrally and deployed across multiple EU markets.
For assistance navigating recent regulatory changes and structuring your AI compliance programme for Romania, contact info@vlolawfirm.com. We can assist with documents and filings.
Does the EU AI Act apply to small and medium-sized enterprises in Romania?
The EU AI Act applies to all providers and deployers of AI systems within its scope, regardless of company size. However, the Act includes some proportionality measures for SMEs and startups, such as reduced fees for conformity assessments and simplified technical documentation requirements in certain cases. Romanian SMEs that develop or deploy high-risk AI systems cannot claim a blanket exemption, but they may benefit from these proportionality provisions. National competent authorities are also expected to provide guidance and support specifically aimed at SMEs. The key practical point is that size does not determine whether obligations apply - it may affect how certain procedural requirements are implemented.
How long does it take to achieve compliance with the AI Act for a high-risk system in Romania?
The timeline for achieving compliance with the AI Act for a high-risk AI system depends heavily on the complexity of the system, the maturity of existing documentation and governance processes, and whether a third-party conformity assessment is required. In practice, businesses that are starting from scratch should expect the process to take several months at minimum. This includes time to conduct a risk assessment, produce technical documentation, implement logging and human oversight mechanisms, and complete the conformity assessment procedure. Registration in the EU database for high-risk AI systems must be completed before the system is placed on the market or put into service. Businesses that have existing quality management systems or ISO certifications may be able to accelerate parts of this process.
What are the penalties for non-compliance with AI regulation in Romania?
The EU AI Act sets out a tiered penalty structure. The most serious violations - such as deploying a prohibited AI system - can attract fines of up to a specified percentage of global annual turnover or a fixed maximum amount, whichever is higher. High-risk system violations and other non-compliance carry lower but still significant maximum fines. Penalties for providing incorrect or misleading information to authorities are also provided for. In Romania, the national competent authority will be responsible for imposing these penalties at the domestic level, with the European AI Office having direct enforcement powers over GPAI model providers. Businesses should note that the Act also allows for orders to withdraw or recall non-compliant AI systems from the market, which can have significant operational and reputational consequences beyond the financial penalty itself.
AI regulation in Romania is now a concrete legal reality, not a future prospect. The EU AI Act applies directly, its most significant obligations are active or imminent, and national enforcement infrastructure is being established. Romanian businesses and foreign companies operating in Romania must assess their AI systems, determine their risk classification, and implement the required compliance measures without delay. The cost of proactive compliance is substantially lower than the cost of enforcement action or market withdrawal.
VLO Law Firms advises international clients on AI regulation in Romania. We can assist with risk classification assessments, compliance programme design, technical documentation review, conformity assessment preparation, and regulatory filings. To request a consultation, contact: info@vlolawfirm.com